From 9a35bb888c807989fe259d7af2942457f5e06f75 Mon Sep 17 00:00:00 2001 From: Mitchell Krog Date: Thu, 4 Jul 2019 13:30:22 +0200 Subject: [PATCH] UPDATE ssl.d/globalssl.conf [ci skip] Recommended SSL settings for all nginx sites --- ssl.d/globalssl.conf | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/ssl.d/globalssl.conf b/ssl.d/globalssl.conf index 4fde985a6..e40b665d3 100644 --- a/ssl.d/globalssl.conf +++ b/ssl.d/globalssl.conf @@ -54,7 +54,7 @@ # include /etc/nginx/ssl.d/globalssl.conf; - ## + ## # DIFFIE HELMAN ENCRYPTION / DHE ## @@ -128,9 +128,9 @@ ssl_stapling on; ssl_stapling_verify on; - # Do not use resolvers for OCSP see comment in - https://scotthelme.co.uk/ocsp-stapling-speeding-up-ssl/ + # Do not use resolvers for OCSP see comment in - https://scotthelme.co.uk/ocsp-stapling-speeding-up-ssl/ # http://disq.us/url?url=http%3A%2F%2Fblog.zorinaq.com%2Fnginx-resolver-vulns%2F%3AP2dn26U8hf5EMF__e_ZIRGBpc3E&cuid=2541595 - # resolver 8.8.8.8 8.8.4.4 valid=300s; - # resolver_timeout 5s; + # resolver 8.8.8.8 8.8.4.4 valid=300s; + # resolver_timeout 5s;